惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

Jina AI
Jina AI
V
Visual Studio Blog
博客园 - 司徒正美
TaoSecurity Blog
TaoSecurity Blog
博客园 - 聂微东
IT之家
IT之家
博客园_首页
Threat Intelligence Blog | Flashpoint
Threat Intelligence Blog | Flashpoint
C
Cyber Attacks, Cyber Crime and Cyber Security
博客园 - Franky
雷峰网
雷峰网
罗磊的独立博客
S
Schneier on Security
C
Cybersecurity and Infrastructure Security Agency CISA
The Cloudflare Blog
T
Tailwind CSS Blog
B
Blog RSS Feed
H
Help Net Security
T
The Blog of Author Tim Ferriss
C
CXSECURITY Database RSS Feed - CXSecurity.com
T
Threatpost
C
CERT Recently Published Vulnerability Notes
博客园 - 三生石上(FineUI控件)
P
Palo Alto Networks Blog
I
Intezer
G
GRAHAM CLULEY
Engineering at Meta
Engineering at Meta
S
Securelist
J
Java Code Geeks
V
V2EX
Y
Y Combinator Blog
Simon Willison's Weblog
Simon Willison's Weblog
L
LINUX DO - 热门话题
云风的 BLOG
云风的 BLOG
Spread Privacy
Spread Privacy
MongoDB | Blog
MongoDB | Blog
P
Privacy International News Feed
cs.CL updates on arXiv.org
cs.CL updates on arXiv.org
B
Blog
Forbes - Security
Forbes - Security
Google Online Security Blog
Google Online Security Blog
Help Net Security
Help Net Security
S
SegmentFault 最新的问题
N
Netflix TechBlog - Medium
Webroot Blog
Webroot Blog
Microsoft Security Blog
Microsoft Security Blog
SecWiki News
SecWiki News
Scott Helme
Scott Helme
aimingoo的专栏
aimingoo的专栏
N
News and Events Feed by Topic

VMware Blogs

Diagnostics for VMware Cloud Foundation (VCF) 9.1 with Old Versions of VCF Components Modernizing the Private Cloud: Why VCF 9.1 Lifecycle Management is a Game Changer Announcing the VMware Cloud Foundation 9.1 Upgrade Planning Tool VCF Breakroom Chats Episode 86 – Containers Made Easy: The New “Container-as-a-Service” in VCF 9.1 Securing Your VCF 9.1 Infrastructure with the Symantec Identity Security Platform Virtually Speaking: The AI Reality Check with Dave Linthicum Zero Touch Provisioning: Activating Edge Sites with VMware Cloud Foundation Edge 9.1 VCF Breakroom Chats Episode 85 – Cloning Success at Scale: Inside VCF 9.1’s App Stack Formation VMware Cloud on AWS の使用状況を確認できる API Unlocking the Full Potential of Programmable Infrastructure with VMware Cloud Foundation 9.1 – New Features and Capabilities Smarter Patching at Scale: Vulnerability Assessment and Remediation with VMware Tanzu Platform Encrypted vMotion Offload to Intel QAT in VMware Cloud Foundation 9.1 Deepen Your Expertise: Four Key Benefits of Attending Increase Deployment Flexibility with VCF Edge Automation 1.0.3 Avi Advantage: Automating Certificate Management of VCF Workloads More Memory, Less Effort: Configuring Memory Tiering in VCF 9.1 VCF 9.1 Licensing: Programmatic, Centralized, and Built to Scale Why APJ Networking Professionals Need Private Cloud Expertise VCF 9.1 Networking: Simpler VPC Connectivity Control VCF 9.1 Networking: Exploring Network Services for Virtual Private Clouds VCF Networking 9.1: Seamless DDI Integration with Infoblox The Open Source Advantage: Building from Source for Ultimate Security Expand Shared VMDKs with Clustered Applications in VMware vSAN for VCF 9.1 Monetizing Zero-Trust Security with VCF 9.1 and VMware vDefend VMware vSAN Protection and Recovery Enhancements for VCF 9.1 Deliver Production SQL Server DBaaS with VMware Data Services Manager 9.1 Maximizing Profitability: VCF 9.1 Cost-Focused Approach for VMware Cloud Service Providers Modernizing Your Infrastructure: Introducing VMware Cloud Foundation 9.1 to VCSPs VCF 9.1 is Available: Explore the New Features in Hands-on Labs What’s New with vSphere in VMware Cloud Foundation 9.1? Resizing VMware vCenter in VMware Cloud Foundation 9 Non-Disruptive VMware vCenter Patching in VMware Cloud Foundation 9.1 VMware vCenter Virtual Hardware Gets an Upgrade in vSphere with VCF 9.1 AI Has Changed the Threat Landscape. Is Your Infrastructure Ready? Simplifying Storage with the New Effective Capacity View in VMware vSAN for VCF 9.1 Auto-RAID in VMware vSAN for VCF 9.1 – Comprehensive System-Managed Data Resilience Introducing VMmark 4.1: Enhanced Power Efficiency Benchmarking for Private Cloud Infrastructure Advanced Memory Tiering Enhancements in VMware Cloud Foundation 9.1 VCF 9.1 Is Here. See It in Action. 博通發布 VMware Cloud Foundation 9.1 How Broadcom Is Helping Enterprises Win the AI Security Sprint How to Prepare for the World of AI Driven Exploits Avi Innovations for VCF 9.1: Powering Kubernetes, Agentic AI and VPC Workloads VCF 9.1: The Secure, Cost-Effective Private Cloud Platform for Production AI Announcing VCF 9.1: Modern Private Cloud Built for Efficiency and Resilience Announcing VMware Cloud Foundation Edge 9.1: A Scalable, Autonomous Edge Platform Accelerate, Streamline, and Control Your Self-Service Private Cloud with VMware Cloud Foundation 9.1 Deploy Modern Apps Faster, Scale Smarter, and Lower Your TCO with VMware vSphere Kubernetes Service in VCF 9.1 Scale Smarter, Save More: Redefining Infrastructure Economics with VMware vSphere in VCF 9.1 AI with VCF 9.1 on AMD GPUs: Build with open frameworks and simplify management, at a lower TCO Streamline, Simplify and Protect all your AI workloads with VCF 9.1 Simplify Workload Connectivity and Enhance Network Scale and Performance with VCF 9.1 VMware and CrowdStrike Deliver New Integration for Cyber Recovery Workflows How Many Users Can Your LLM Server Really Handle? From Infrastructure to Agents: A Hands-On Guide to Secure Private AI with Broadcom – Part 2 The New Frontier: Leading the Cloud-Native Evolution Replicating VMware vSphere Configuration Profile Desired State Webinar Recap: Design and Architecture Considerations for VMware vSphere Kubernetes Service on VMware Cloud Foundation Kubernetes 1.36: What Actually Changed for Enterprise Platforms Enhance Lateral Security and Ingress Load Balancing for Kubernetes Workloads Avi Load Balancer Analytics: Root Cause Application Performance Issues in Minutes Analyst Insight Series #3: Policy-Driven Governance and Multi-Tenant Control Post-Quantum Readiness on VMware Cloud Foundation Registration Is Live for Las Vegas | $ave with Early-Bird May 21, 2026: What’s New in VMware Tanzu Data Intelligence 10.4 From Infrastructure to Agents: A Hands-On Guide to Secure Private AI with Broadcom – Part 1 Stop Guessing: Advanced Monitoring and Troubleshooting for Data Services CPU, Disk, Network, and Memory Workload Profiles for DVD Store Database Testing How VMware Salt Automates Compliance Across Private Cloud Analyst Insight Series #2: Operational Scalability and Lifecycle Management MCP vs. APIs: Why You Need Both for AI Applications The Real Constraint on Enterprise AI isn’t GPUs; It’s Power Deploying Harbor Service in Air-Gapped VMware Cloud Foundation 9.0 Why Enhanced DirectPath Wins for High-Performance Apps Bridging the (.Local) Gap: A Split-Domain Design for VMware Cloud Foundation Deployment Observability on VMware vSphere Kubernetes Service VMware Cloud on AWS: Introducing the Usage Report APIs Converging VMware vSphere to VMware Cloud Foundation 9.0: The Top 10 Questions Answered May 6, 2026: What’s New in Tanzu Platform 10.4: Powering Agentic Apps at Scale VMware Tanzu RabbitMQ Powers the Modern Data Lakehouse with New Spark Integration and Enterprise Tooling Tanzu Data Intelligence 10.4 Delivers AI-Driven Analytics, Unified Real-Time Operations, and Sovereign Resilience Enterprise-Ready Agents Made Simple & Safe with VMware Tanzu Platform Agent Foundations Introducing Tanzu Platform 10.4: Extending Platform as a Service to Agentic Applications How AI-Assisted Analytics in Tanzu Data Intelligence Can Help Remove the SQL Bottleneck From Prototype to Production: Securing Database MCP at Enterprise Scale The Compelling Case for a Private Cloud Data Intelligence Platform The Unification Dividend: Consolidating Database Operations on VMware Cloud Foundation The Modern Spring Workflow Is Enterprise-Ready and AI-Boosted [TAM Blog] セキュアブート証明書の有効期限切れに関する注意点と対応について Accelerate Lateral Security and Ingress Load Balancing for Kubernetes Workloads From Platform to Data: Building a Cloud-Native Developer Experience On-Prem with VMware Cloud Foundation How VMware Cloud Foundation (VCF) Training Helps Keep Top Tech Talent in APJ Build Your Case for Attending VMware Explore 2026 Spring 開発元が提供する商用サポート「VMware Tanzu® Spring Essentials」とは VMware Cloud on AWS より i7i.metal-24xl インスタンスの提供開始 VMware Advanced Memory Tiering Tips for Success VMware Cloud Foundation Edge 9.0: Two-Host Edge Site Deployment with Brownfield Import Your Database Is About to Become an AI Tool. Is It Ready? Applying GitOps Principles to Maintain Desired State Configuration using VMware vSphere Configuration Profile – Part 3 Webinar Recap: Converging VMware vSphere to VMware Cloud Foundation 9.0
Mastering Infrastructure Policies in VMware Cloud Foundation Automation 9.1
Scott McDermott · 2026-05-29 · via VMware Blogs

With the release of VMware Cloud Foundation (VCF) 9.1, VMware has introduced a modernized management architecture designed to streamline private cloud operations. Among the most exciting features are the new Infrastructure Policies. Let’s look at the benefits of integrating Infrastructure Policies into your environments to ensure optimal workload placement, license compliance, and governance.

The new VCF Automation Infrastructure Policies provide the ability for administrators to dynamically govern VM placement across various zones. Whether you are aiming for license optimization by pinning Windows workloads to specific hosts, or ensuring regulatory compliance by strictly controlling where specific apps reside, Infrastructure Policies allow you to enforce these rules systematically without manual toil.


Table of contents

  • Bridging the Gap: VCF Automation Infrastructure Policies and vSphere Compute Policies
  • Provider Administrator
    • Optional vs. Mandatory Policies
    • Using the Criteria Builder
    • Apply Policies to the Region Quota
  • Organization Administrator: Adding Infrastructure Policies to Namespaces
  • Organization User: Consuming Infrastructure Policies in Deployments
  • Complete Example Workflow
    • Try It Out in VMware Hands-on Labs

Bridging the Gap: VCF Automation Infrastructure Policies and vSphere Compute Policies

Historically, Infrastructure Administrators have created Compute Policies to ensure workloads are placed on compatible hosts. These policies are based on key value pairs like category and tag, where administrators can create categories and tags for host and VMs to ensure the host tags running the VM are compatible with the tags applied to the VM.

vSphere Compute Policies
Compute Policies in vSphere

Now, let’s review how VCF Automation interacts with your underlying infrastructure. An Infrastructure Policy in VCF Automation acts as a bridge to your vCenter configurations. It is comprised of two core components:

  1. Matching Criteria: The logic that defines which workloads the policy applies to (e.g., all VMs with a Linux Guest OS).
  2. Compute Policy Reference: A direct link to an underlying VM-Host affinity compute policy residing in vCenter.

When you configure a policy in VCF Automation, you are essentially wrapping a vSphere compute policy in a layer of cloud-consumption logic. This ensures that when a user requests a VM in the cloud portal, VCF Automation passes the requirements down to vCenter, which then enforces the placement using host tags.

Infrastructure Policies in VCF Automation

Provider Administrator

As a Provider Administrator, your primary goal is to set up the guardrails for the underlying infrastructure. In the Provider Management UI, you have extensive control over how Infrastructure Policies are enforced.

Optional vs. Mandatory Policies

When creating a policy, you must decide how strictly it should be enforced across a region:

  • Mandatory Policies: If you check “Make this a mandatory policy when assigned to a region,” the policy is always enforced when a new namespace is created within that region’s quota. If the requested zones do not have the required host tags to satisfy the underlying vCenter compute policy, namespace creation will outright fail. This is ideal for strict compliance or licensing rules.
  • Optional Policies: If left unchecked, the policy is available but not enforced by default. Organization Administrators can choose to opt-in and apply the policy to specific namespaces as needed.
Mandatory Infrastructure Policy
Create a mandatory Infrastructure Policy

Using the Criteria Builder

To ensure infrastructure policies only affect the intended workloads, the Provider Administrator uses the Criteria Builder. This tool allows you to add rules to determine which VMs the policy manages. You can define conditions by selecting specific VM attributes (such as Guest OS, Guest OS Family, or Custom Label) and pairing them with operators. For instance, you might build an expression like: (GuestOSFamily IS_EQUAL "Linux“). The criteria builder includes an expression preview feature so you can verify the intended rules before saving the policy.

Infrastructure Policy Criteria Builder
Infrastructure Policy Criteria Builder

Apply Policies to the Region Quota

With the Infrastructure Policies created, the Provider Administrator can then apply the desired policies to each Organizations Region Quota. Once the policies are applied, the Organization Administrators can apply them to the desired Namespaces. One thing to note here is that mandatory policies can only be applied to Region Quotas without existing Namespaces.

VCF Automation Region Quota Infrastructure Policies
Region Quota Infrastructure Policies

Organization Administrator: Adding Infrastructure Policies to Namespaces

To expand on the Provider Administrator’s setup, let’s look at how Organization Administrators govern their specific application teams.

Org Admins are responsible for managing namespace resources to accommodate changing application demands. To assign these placement rules:

  1. Navigate to Manage & Govern > Namespaces and click the namespace you want to edit.
  2. Click the vertical ellipsis next to the namespace name and select Edit.
  3. Scroll to the Infrastructure Policies section.
  4. Here, you can add or remove the optional policies assigned to the region quota by the Provider Admin.
    • Mandatory Policies are automatically included in all namespaces provisioned in the region and cannot be removed by the Organization Administrator.
Define optional Infrastructure Policies available in a Namespace
Define optional Infrastructure Policies available in a Namespace

Organization User: Consuming Infrastructure Policies in Deployments

Now let’s put this into the hands of the end users. Application teams and developers interact directly with Infrastructure Policies during the self-service provisioning process.

When a user logs in to provision a VM or application stack, they specify their workload requirements. Then magic happens in the background:

  • Self-Service Provisioning: The user selects their desired image.
  • Zone Selection: In the deployment wizard, the user can set the Zone to Automatic.
  • Policy Evaluation: VCF Automation evaluates the VM’s attributes against the active infrastructure policies on the namespace. If the VM is a Linux machine and matches a mandatory placement policy, the system automatically selects a zone and cluster that satisfies the underlying vSphere compute policy.
Provision a VM with Infrastructure Policies
Provision a VM with Infrastructure Policies

If users need to edit their deployment’s optional Infrastructure Policies (Day-2 operations), VCF Automation continuously evaluates the policies. If an update changes a VM’s attributes (e.g., changing an Infrastructure Policy assignment), the system will ensure the workload remains compliant with the placement rules, migrating it if necessary and supporting it with the underlying zone configuration.

Review applied Infrastructure Policies
Review applied Infrastructure Policies

Complete Example Workflow

Now let’s put all of this together in a complete operational example.

  1. Infrastructure / Operations Admin applies tags in vCenter and creates VM-Host affinity Compute Policies.
  2. Provider Admin creates Infrastructure Policies linked to the vSphere Compute Policies, and uses the Criteria Builder to create rules.
  3. Provider Admin assigns the policies to the Organizations Region Quotas.
  4. Organization Admin creates a new project namespace. Because the policy is mandatory, VCF Automation verifies that the selected zones have hosts capable of satisfying the rule.
  5. Organization User requests a new VM and applies the desired optional policies.
  6. VCF Automation intercepts the request, applies the policy, selects the compliant zone automatically, and instructs vCenter to place the VM on a compliant host.

By leveraging Infrastructure Policies in VCF 9.1, you can provide a seamless, public cloud like experience for your users while maintaining absolute control over your private cloud!


Try It Out in VMware Hands-on Labs

What’s New in VMware Cloud Foundation 9.1: Highlights (HOL-2701-01-VCF-L)

Module 3 for VCF Automation reviews optional Infrastructure policies along with many other great features for the 9.1 release.


Discover more from VMware Cloud Foundation (VCF) Blog

Subscribe to get the latest posts sent to your email.